cbcvebase.
CVE-2024-35838
published 2024-05-17

CVE-2024-35838: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station without ever marking links valid, and leak them. Fix that.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= cb71f1d136a635decf43c3b502ee34fb05640fcd < 49aaeb8c539b1633b3bd7c2df131ec578aa1eae149aaeb8c539b1633b3bd7c2df131ec578aa1eae1
linuxlinux>= cb71f1d136a635decf43c3b502ee34fb05640fcd < 587c5892976108674bbe61a8ff659de279318034587c5892976108674bbe61a8ff659de279318034
linuxlinux>= cb71f1d136a635decf43c3b502ee34fb05640fcd < e04bf59bdba0fa45d52160be676114e16be855a9e04bf59bdba0fa45d52160be676114e16be855a9
linuxlinux>= cb71f1d136a635decf43c3b502ee34fb05640fcd < b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 6.0 < 6.1.766.1.76
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.